Live data from Hacker News

Facebook security hole allows viewing of private photos

forum.bodybuilding.com

31–40 of 143 posts

Re: Facebook security hole allows viewing of private photos

#31

Funny how something like this is originally posted on a body building forum. I think the first reports of the recent Penn State scandal were posted there too (around a year ago.) Who would have thought that's where you'd first find such things?

Bodybuilding.com started as a forum about bodybuilding, but over the years morphed into a large general message board with all sorts of members.

Behold, "misc," the /b/ of bodybuilding.com: http://forum.bodybuilding.com/forumdisplay.php?f=19

Re: Facebook security hole allows viewing of private photos

#32

General form appears to be as follows: http://www.facebook.com/ajax/report/social.php? __a=1& __d=1& attach_additional_photos=1& cid=((FBID))& content_type=0& h=((HASH BASED ON YOUR ACCOUNT))& phase=6& report_id=1& rid=((FBID)) After you get that initial hash then you can swap out the CID and the RID and get everyone else (I tried it for 3)... it's pretty easy. This issue is probably going to make mainstream news by…

[deleted]

Re: Facebook security hole allows viewing of private photos

#33

General form appears to be as follows: http://www.facebook.com/ajax/report/social.php? __a=1& __d=1& attach_additional_photos=1& cid=((FBID))& content_type=0& h=((HASH BASED ON YOUR ACCOUNT))& phase=6& report_id=1& rid=((FBID)) After you get that initial hash then you can swap out the CID and the RID and get everyone else (I tried it for 3)... it's pretty easy. This issue is probably going to make mainstream news by…

What is the "hash"? An md5 of username? Or what?

Re: Facebook security hole allows viewing of private photos

#34
post #24

This is a security hole and nothing more. Developers make mistakes. This is not some vast conspiracy by Facebook to undermine your privacy. Why, of all places, is HackerNews unable to comprehend this?

I think it's a stretch to call this "just" a mistake. First of all, there isn't any malicious code that has to be run to execute it, it's a simple as clicking a few buttons in the UI. Secondly, Facebook is a site with hundreds of millions of users managing billions of private photos. With the amount of revenue & number of developers they have, it's inexcusable that they can't think through a simple process like this…

I'm downvoting you for saying I think it's a stretch to call this a mistake

If it wasn't on purpose, it was a mistake. Period.

It might be inexcusable, as you later pointed out, but it was still unintentional. Everyone likes to hate on Facebook. If this was a YC startup, I suspect people would be more forgiving.

Re: Facebook security hole allows viewing of private photos

#35

This is a security hole and nothing more. Developers make mistakes. This is not some vast conspiracy by Facebook to undermine your privacy. Why, of all places, is HackerNews unable to comprehend this?

If you see a comment that makes it sound like there's a vast conspiracy, please post in reply to that comment. I don't see any such comment. HN appears to be comprehending just fine.

Re: Facebook security hole allows viewing of private photos

#36

This is a security hole and nothing more. Developers make mistakes. This is not some vast conspiracy by Facebook to undermine your privacy. Why, of all places, is HackerNews unable to comprehend this?

No. This shows that Facebook has no robust security model at all. Either they do not have any mandatory access control for private data, or someone approved of circumventing such access control measures for this feature. Both is in my opinion inacceptable for a company holding so much potentially sensitive data.

Re: Facebook security hole allows viewing of private photos

#37

Facebook is an excellent personal marketing tool. However, I think at this point you'd have to be a fool to put material on it you want to be private. Of course, what PT Barnum said....

"Of course, what PT Barnum said..."

Or possibly didn't say:

http://en.wikipedia.org/wiki/Theres_a_sucker_born_every_minu...

Re: Facebook security hole allows viewing of private photos

#38
post #34
post #24

Earlier quoted context omitted.

I think it's a stretch to call this "just" a mistake. First of all, there isn't any malicious code that has to be run to execute it, it's a simple as clicking a few buttons in the UI. Secondly, Facebook is a site with hundreds of millions of users managing billions of private photos. With the amount of revenue & number of developers they have, it's inexcusable that they can't think through a simple process like this…

I'm downvoting you for saying I think it's a stretch to call this a mistake If it wasn't on purpose, it was a mistake. Period. It might be inexcusable, as you later pointed out, but it was still unintentional. Everyone likes to hate on Facebook. If this was a YC startup, I suspect people would be more forgiving.

If it wasn't on purpose, it was a mistake

I think the problem is that calling it a mistake downplays the issue. I'd say this is grave negligence, because besides the feature itself, it shows a lack of access control systems.

Re: Facebook security hole allows viewing of private photos

#39

This is a security hole and nothing more. Developers make mistakes. This is not some vast conspiracy by Facebook to undermine your privacy. Why, of all places, is HackerNews unable to comprehend this?

There is a lot of muscle memory to overcome here. It's like Jeffrey Dahmer accidentally killing someone. You can't blame people for jumping to conclusions.

Re: Facebook security hole allows viewing of private photos

#40
post #34
post #24

Earlier quoted context omitted.

I think it's a stretch to call this "just" a mistake. First of all, there isn't any malicious code that has to be run to execute it, it's a simple as clicking a few buttons in the UI. Secondly, Facebook is a site with hundreds of millions of users managing billions of private photos. With the amount of revenue & number of developers they have, it's inexcusable that they can't think through a simple process like this…

I'm downvoting you for saying I think it's a stretch to call this a mistake If it wasn't on purpose, it was a mistake. Period. It might be inexcusable, as you later pointed out, but it was still unintentional. Everyone likes to hate on Facebook. If this was a YC startup, I suspect people would be more forgiving.

That's true, if it was a group of three young people starting a new business, I would be more forgiving than about a multi billion dollar corporation with hundreds of engineers and millions in resources.

It was a mistake, but another word for a mistake is 'negligence'. The fact that something like this can happen illustrates systemic shortcomings at the company. Millions of people are depending on them to enforce the privacy restrictions Facebook claims to enforce. Facebook encourages you to store highly personal data, and as such, they have a responsibility to be more careful. Facebook prides themselves on constantly pushing changes to their software. More safeguards, testing, and perhaps slowing down the software development cycle a little would not be a bad idea.

Post reply on HN